Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9542 Source: MSExchangeIS

Source
Level
Description
Initialization of external interface NNTP failed; Error ecNotInitialized-MAPI_E_NOT_INITIALIZED.
Comments
 
This is caused by a value being set in one of the following attributes (visible via ADSI Edit on the information store properties of the server in question):

msExchMaxThreads
msExchMinimumThreads
MSExchPoolThreads

Each of these should be clear but if a value too low is set, it can prevent the databases from mounting even though the IS service is running. This was outlined in ME319760 but that article has been pulled as of 6/20/06.
This problem may occur when an antivirus program is configured to include scans of Exchange Server folders and files. See ME919076 to find out how you can solve this problem.

This event might occur if you install the Microsoft Data Access Components (MDAC) 2.7 update. See ME320204 for a workaround.

This problem can occur if the Exoledb library does not initialize. When the Exoledb library initializes, it scans the HKEY_CLASSES_ROOT (HKCR) registry hive for content class information. If the Exoledb library finds a ProgID with a value that exceeds 259 characters, the Exoledb library cannot initialize. See ME290105 for details on this situation.
As per Microsoft: "This event can manifest itself in a few different ways. The underlying cause of the problem will depend on the information in the description line. There will, as well, be other events in the application log, which can provide information. In post-release versions of Exchange Server, this problem can occur if the msExchMaxThreads and msExchMinimumThreads values of the server's object in Active Directory have incorrect values. The default values are 100 and 10, respectively. Lastly, this event can occur if the HKEY_LOCAL_MACHINE\Software\Microsoft\Exchange\Setup key has a "Services" string value that has incorrect data, or has correct data but the permissions on this key are not set correctly". See MSEX2K3DB for more details on this event.

See ME305030, ME837285, and ME888179 for information on fixing this problem.
As per Microsoft: "Cause: The Services string type value located in the following registry key is missing or inaccessible:  HKEY_LOCAL_MACHINE\Software\Microsoft\Exchange\Setup". See ME285116 and ME823159 for more info.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...